You don’t need any of this stuff. Caddy handles the XFF header automatically for you when trusted_proxies is properly configured. Since you’re fronting with Cloudflare, you should use the client_ip_headers option to tell Caddy to read from Cf-Connecting-Ip when trusted. See Global options (Caddyfile) — Caddy Documentation. Also, you can simplify your IP list by using the GitHub - WeidiDeng/caddy-cloudflare-ip plugin instead of listing them all out.
Remove all this stuff. Caddy already handles those headers for you. See reverse_proxy (Caddyfile directive) — Caddy Documentation